Uptime Hamster: 10d 19h 53mDeploy: 14 Jul 2026 21:26Updated: 2026-07-21
Logo del actor de amenaza blackbyte

blackbyte

3 incidentes 1 paises 1 sectores ransomware RU Ultimo: 2026-07-09
Aliases: Hecamede, DEV-0569, Conti, Quantum, Black Byte, Diavol, Black Basta, Ryuk (como FIN12)
Ver en IntelTracker → APTTrail →
BlackByte is a financially motivated ransomware-as-a-service (RaaS) operation that first emerged in July 2021, evolving rapidly from initial C# implementations to more sophisticated variants written in Go, .NET, and C++. The group is assessed with high confidence to be of Russian origin, given its observed avoidance of systems configured with Russian and certain Eastern European languages. BlackByte initially used a simple symmetric encryption key that allowed security researchers to develop a public decryptor, prompting the group to significantly update its encryption methods and implement a more robust BlackByte 2.0. This group distinguishes itself by continually incorporating newly disclosed vulnerabilities into its attack chains and offering unique, flexible extortion options to victims, such as paying to delay data publication or to download and destroy stolen information, beyond the standard double extortion model of data encryption and exfiltration. BlackByte is not known to ope

Aliases del actor

HecamedeDEV-0569ContiQuantumBlack ByteDiavolBlack BastaRyuk (como FIN12)

Actores similares

blackbyte-cruxactor · 1blackbastaransomware · 523BlackBastaactor · 2blacksuitransomware · 184blacknevasransomware · 16blackwaterransomware · 11black-xactor · 8blackshrantacransomware · 8blackoutransomware · 5blackfieldactor · 3

Canales, DLS e infraestructura asociada

Clasificacion automatica desde IntelTracker/APTTrail/OSINT. Estado real solo si viene indicado por la fuente.

TipoEstadoHost / enlaceTitle / ultimo titulo
Repositoriounknowngithub.comRansom Notes: blackbyte (4 notes from ThreatLabz)
Malware asociado
Mimikatz
Tecnicas MITRE
T1518.001, T1036.008, T1543.003, T1505.003, T1543, T1140
Victimas
2
TTPs unicas
0
Info robada historica
N/D
Rescates reclamados
N/D
Pagos detectados
N/D

Paises afectados

United States (2)

Paises objetivo (SOCRadar)

United Arab EmiratesAnguillaArgentinaAustriaAustraliaBahrainBrazilBotswanaCanadaSwitzerland

Sectores atacados

Software (1)

Sectores objetivo (SOCRadar)

Construction of BuildingsFood ManufacturingOther Information ServicesMonetary Authorities-Central BankRail TransportationSoftware PublishersReal EstateHospitalsEnterprises & HoldingAccommodation

URLs nuevas detectadas en IntelTracker

github.com

Victimas (2)

BlackByte (Unknown / Unmapped Actors)9 Jul 2026
Reference United States
Que es BlackByte es un actor APT (Advanced Persistent Threat) cuya actividad se vincula con ataques cibernéticos de alto nivel. Se identifica como un …
Ransom Notes: blackbyte (4 notes from ThreatLabz)18 Jun 2026
Report
blackbyte - Ransom NotesEste grupo de ransomware tiene 4 notas de rescate documentadas en el repositorio ThreatLabz/ransomware_notes. Las notas de res…